Pwning Malware with Ninjas and Unicorns
ID: a26452d3-6a14-5ca4-b951-87aa68065d57
STIX ID: report--a26452d3-6a14-5ca4-b951-87aa68065d57
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
This report documents a DFIR-driven reverse engineering effort against a packed ELF64 Linux malware (likely a new SysUpdate variant). The analyst details static and dynamic analysis that identified custom key-generation and an XOR-based encryption/decryption routine, and demonstrates building Unicorn Engine (Rust) emulators and Binary Ninja/GDB-assisted memory carving to generate the malware's key material and decrypt intercepted C2 traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
